> Source: [sk179801](https://support.checkpoint.com/results/sk/sk179801)

# sk179801 - Traffic with destination NAT does not work with VTI (route based VPN)

| Property | Value |
|----------|-------|
| Solution ID | sk179801 |
| Date Created | 2022-08-09 |
| Last Modified | 2023-02-04 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * A VTI (Route based VPN) tunnel is established, but the VPN Gateways do not encrypt traffic. The VPN Gateways drop traffic from the tunnel because of the Cleanup Rule.
* There is a relevant NAT rule which is not enforced correctly. After disabling the destination NAT address and changing it as the original IP address, the VPN Gateways encrypt and receive traffic as expected.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect CPinfo file from the Security Gateways involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
